Privacy Policy
Last updated: 2026-08-15
1. Who we are
Trident Foresight (the “Service”) is operated by Trident BI Limited(“Trident BI”, “we”, “our”), a company registered in England & Wales. For questions about this policy, or to exercise a data-subject right, contact dean@tridentbi.com.
2. Roles under data-protection law
For personal data of the merchant admin user (name, email, Shopify account details), Trident BI is the data controller.
For personal data of a merchant's end customers, the merchant is the data controller and Trident BI acts as a data processor. In practice, the Service does not require or handle customer-level personal data — it operates on public product-catalog data. If we ever receive customer personal data as a side effect of a Shopify webhook payload we do not need, we discard it without persistence.
3. What we collect
From Shopify at install:
- Your shop's
*.myshopify.comdomain - An offline access token scoped to
read_products, and optionallywrite_productsandread_orders - The merchant email associated with the install
- Your shop's primary currency and locale (for display formatting)
Via the granted scopes:
read_products— your product catalogue metadata (title, vendor, handle, price range, image) for side-by-side matching against competitor SKUswrite_products(optional, only if granted) — used exclusively when you tap Apply on a defensive reprice; never used autonomouslyread_orders(optional, only if granted) — order line-item quantities from the last 90 days, aggregated into per-SKU weekly velocity. We do not store customer PII, addresses, payment details, or shipping information from orders — onlyproduct_id,quantity, andcreated_at.
Configuration you provide:
- Competitor domains you elect to track
- Optional Slack webhook URL, digest email address, alert rules
- Defense guardrails (price floor %, excluded product IDs and tags, max daily reprice count)
- Outgoing webhook URLs and generated secrets
- API tokens (name only; the token value is hashed at rest)
Automatically generated by use of the Service:
- Product snapshots and change events observed on the competitors you track
- Model prediction logs and defense audit trail
- AI-generated daily narratives (cached one per store per day)
- Delivery logs for alerts and outgoing webhooks
- Aggregate usage counters and audit-log entries
The Service does not deploy tracking cookies, analytics beacons, session-replay tools, or advertising pixels within the merchant admin interface. Cookies used are strictly necessary for authentication and a per-admin impersonation flag.
4. How we use it
- Provide the Service you install, including polling public product feeds, generating predictions, delivering alerts and digests, and running defensive reprices you authorise
- Detect and prevent abuse, security incidents, and violations of the Terms of Service
- Improve the model, product, and reliability of the Service in the aggregate — never using merchant-specific data to train models that would benefit other merchants
- Communicate service-related notices (billing, outages, security)
- Comply with legal obligations
We do not sell your data. We do not share your data with advertisers. We do not use your data to train third-party AI models. Anthropic's API is called with contractual data-retention and no-training terms (Anthropic's Zero-Data-Retention arrangement where available for your account).
5. Legal bases (UK/EU GDPR)
- Contract: processing necessary to provide the Service you install and use.
- Legitimate interests: operating, securing, and improving the Service; preventing fraud and abuse; measuring aggregate performance.
- Legal obligation: responding to lawful requests, tax and accounting record-keeping.
- Consent: where required (e.g. optional Shopify scopes such as
read_orders— granted only if you approve the scope prompt).
6. Sub-processors
We use the following sub-processors to operate the Service. We only share the minimum data needed for each provider's function.
- Shopify Inc. — the platform you install on; source of merchant credentials and product/order data
- Vercel Inc. — application hosting, edge network, cron scheduling (US regions)
- Neon Inc. (on AWS
us-east-1) — managed Postgres database. SOC 2 Type II. - Anthropic PBC — LLM inference for the daily narrative. Data retention: as per Anthropic's API terms; not used for training.
- Resend, Inc. — transactional email delivery (digest and alerts).
- Slack Technologies, LLC — only if you configure a Slack webhook, and only for the specific messages you have opted in to receive.
Sub-processor changes will be reflected on this page. Continued use after a change constitutes acceptance.
7. International transfers
Data is stored primarily in AWS us-east-1(United States). Where personal data is transferred out of the UK or EEA, we rely on the UK Addendum to the EU Standard Contractual Clauses (or the SCCs directly, as applicable) and each sub-processor's corresponding transfer safeguards.
8. Retention
Active accounts:
- Free plan: 30 days rolling for change events, product snapshots, and prediction logs
- Pro plan: 90 days rolling
- Plus plan: 180 days rolling
- Configuration (competitors, guardrails, alert rules, webhook subscriptions) is retained for the life of the install
- Audit logs and delivery logs: 90 days
- AI narrative cache: 30 days rolling
On uninstall:all merchant data is permanently deleted within forty-eight (48) hours, in fulfilment of Shopify's shop/redact webhook. Encrypted database backups may retain deleted data for up to thirty (30) additional days as part of standard database-vendor backup retention, after which they roll off.
9. Security
We use industry-standard technical and organisational measures, including: TLS 1.2+ for all data in transit; encryption at rest for database storage; access-token hashing where practical; principle-of-least-privilege for internal access; HMAC-SHA256 signing on outgoing webhooks; and audited authentication via Shopify session tokens. No system is perfectly secure — you are responsible for keeping your Shopify account, integration secrets, and API tokens confidential.
Breach notification: in the event of a personal-data breach that presents a risk to affected individuals, we will notify affected merchants and, where legally required, the applicable supervisory authority within seventy-two (72) hours of becoming aware of the breach.
10. Your rights
Depending on your location, you may have the right to: access the data we hold about you; correct inaccurate data; delete your data; restrict or object to certain processing; receive a portable copy of your data; withdraw consent (where processing is consent-based); and lodge a complaint with a supervisory authority.
UK residents: the supervisory authority is the Information Commissioner's Office (ico.org.uk). EEA residents: your national data-protection authority. California residents have additional rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of “sale” or “sharing” of personal information. Trident BI does not sell or share personal information as defined under the CCPA.
To exercise any right, email dean@tridentbi.comfrom the address on your account. We will respond within thirty (30) days.
11. Shopify-mandated GDPR webhooks
customers/data_request— we do not routinely hold customer-level personal data. If we do hold data related to a specific customer, we will respond with an export within thirty (30) days.customers/redact— we have no customer-level data to redact by design; the endpoint accepts and acknowledges the request but performs no data operation.shop/redact— 48 hours after uninstall, all of your shop's data (competitors, products, snapshots, events, predictions, guardrails, settings) is permanently deleted from operational storage; encrypted backups roll off within a further 30 days.
12. Children
The Service is intended solely for use by business operators. It is not directed to children under 16, and we do not knowingly collect personal information from children.
13. AI-generated content and inference data
The daily narrative summary is generated by Anthropic's Claude API. Only aggregated statistics derived from your public competitor data (per-competitor event counts, top price drops) are transmitted to Anthropic. No customer PII, order details, or merchant credentials are ever sent to Anthropic. Anthropic's API terms provide that submitted data is not used to train their foundation models.
14. Changes to this policy
We may update this policy. Material changes will be surfaced in the app, and the “Last updated” date above will be revised. Continued use after a material change constitutes acceptance.
15. Enterprise merchants — DPA
A separate Data Processing Agreement supplements this Privacy Policy for Merchants who require processor-specific commitments under UK/EU GDPR (Article 28) or equivalent regimes. The DPA is accepted automatically on acceptance of the Terms of Service. A countersigned copy is available on request for enterprise procurement.
16. Contact
Privacy questions, deletion requests, data-subject requests, or anything else: dean@tridentbi.com. Postal correspondence available on request.

